Existing law generally regulates social media platforms, including by requiring a social media company to post terms of service for each social media platform owned or operated by the company in a manner reasonably designed to inform all users of the social media platform of the existence and contents of the terms of service, as prescribed. Existing law generally prohibits a person from using violence or intimidation to interfere with another person's enjoyment of certain rights or because of certain attributes of that person, including the person's political affiliation, race, or sexual orientation, and punishes violations of that law with certain civil penalties or as misdemeanors, as prescribed. This bill would make a social media platform, as defined, that violates the above-referenced provisions of law relating to personal rights through its algorithms that relay content to users or aids, abets, acts in concert, or conspires in violation of those laws, or is a joint tortfeasor in an action alleging a violation of those laws, liable for specified civil penalties. The bill would declare its provisions to be severable and would declare attempted waiver of its provisions to be void and unenforceable. This bill would become operative on January 1, 2027.
Existing law prescribes the procedures for circulating an initiative, referendum, or recall petition for signature by voters. This bill would require the Secretary of State to develop a system that allows a proponent of a state or local initiative, referendum, or recall petition to have the petition posted on the Secretary of State's internet website where a voter can electronically sign the petition. The bill would require the Secretary of State and elections officials to perform specified tasks in connection with the electronic circulation of petitions, including verifying the electronic signatures, as specified. By imposing additional duties on elections officials, this bill would impose a state-mandated local program. The California Constitution requires the state to reimburse local agencies and school districts for certain costs mandated by the state. Statutory provisions establish procedures for making that reimbursement. This bill would provide that, if the Commission on State Mandates determines that the bill contains costs mandated by the state, reimbursement for those costs shall be made pursuant to the statutory provisions noted above.
Existing law requires a law enforcement agency, as defined, to obtain specific approval of a governing body prior to acquiring military equipment, as specified. Existing law defines "military equipment" to include an unmanned, remotely piloted, powered aerial or ground vehicle. This bill would prohibit a law enforcement agency from purchasing, on or after January 1, 2027, an uncrewed, remotely piloted, powered aerial or ground vehicle unless the vehicle contains an option to turn off any data collection programs that are not necessary for the vehicle to function and the law enforcement agency uses an American data storage company, as defined, to house all data collected, including, but not limited to, video and photographic images, as specified, or both. For uncrewed, remotely piloted, powered aerial or ground vehicles purchased on or after January 1, 2026, and before January 1, 2027, the bill would require a law enforcement agency to use an American data storage company. For uncrewed aerial or ground vehicles owned or possessed by a law enforcement agency prior to January 1, 2026, the bill would require the law enforcement agency to use an American data storage company after the current contract to house the data expires. The bill would require contracts entered into pursuant to these provisions with an American data storage company to prohibit the American data storage company from using, selling, renting, trading, or otherwise sharing this data with any other entity.
Existing law establishes the Division of Labor Standards Enforcement within the Department of Industrial Relations. Existing law authorizes the division, which is headed by the Labor Commissioner, to enforce the Labor Code and all labor laws of the state, the enforcement of which is not specifically vested in any other officer, board, or commission. This bill would generally regulate the use of workplace surveillance tools and an employer's use of worker data. The bill would, among other things, require an employer, at least 30 days before introducing a workplace surveillance tool, to provide a worker who will be affected a written notice that includes, among other things, a description of the worker data to be collected, the intended purpose of the workplace surveillance tool, and how this form of worker surveillance is necessary to meet that purpose. The bill would define "employer" to include public employers, as specified. The bill would prohibit an employer from transferring, selling, disclosing, or licensing worker data to a vendor, unless the vendor is under contract to analyze or interpret the worker data and the contract includes certain terms. The bill would prohibit an employer from using certain workplace surveillance tools, including a workplace surveillance tool that incorporates facial, gait, or emotion recognition technology, except as specified. The bill would also prohibit an employer from using a workplace surveillance tool to infer specified categories of information about a worker, including, among others, their immigration status, veteran status, ancestral history, religious or political beliefs, disability status, criminal record, or credit history. The bill would require the Labor Commissioner to enforce the bill's provisions, would authorize an employee to bring a civil action for specified remedies for a violation of the bill's provisions, and would authorize a public prosecutor to enforce the provisions. The bill would subject an employer who violates the bill's provisions to a civil penalty of $500 for each violation. The bill would define various terms for purposes of its provisions.
Existing law, the Digital Equity Bill of Rights, provides that it is the principle of the state to ensure digital equity for all residents of the state, that, among other things, residents have access to broadband that meets specific requirements, and provides that it is the policy of the state that, to the extent technically feasible, broadband internet subscribers benefit from equal access to broadband internet service within the service area of a broadband provider. This bill, contingent upon funding for this purpose, would require a broadband internet service provider, on or before January 1, 2027, and annually thereafter, to submit to the Department of Consumer Affairs, or the Department of Broadband and Digital Equity if Assembly Bill 693 of the 2025–26 Regular Session is enacted, a report containing broadband internet access service pricing and speed data that includes, among other information, the advertised speeds offered to consumers and the advertised and total prices paid by consumers. The bill would require the department to publish an annual broadband internet access service affordability and speed report aggregating and analyzing the data submitted by the broadband internet service providers and would require the department to make the data submitted by broadband internet service providers available to the public, as specified. The bill would make a broadband internet service provider that fails to comply with these provisions subject to an administrative penalty not to exceed $1,000 per violation per day until compliance is achieved. This bill would require a broadband internet service provider to establish and maintain a dedicated consumer complaint resolution process that allows consumers to submit complaints via telephone, email, and an online portal, and would require a broadband internet service provider to respond to a complaint within 7 business days and provide a resolution, explanation, or corrective action within a specified timeframe. The bill would prescribe remedies for a consumer if a broadband internet service provider fails to resolve a complaint within the specified timeframe or refuses to act in good faith, including the issuance of a minimum credit of $50 for a complaint that remains unresolved beyond 60 days without valid justification. The bill would require a broadband internet service provider to disclose the complaint resolution process and remedies clearly and conspicuously in its terms of service, in its billing statements, and on its internet website. The bill would require a broadband internet service provider to report complaint statistics to the department, as specified. Existing constitutional provisions require that a statute that limits the right of access to the meetings of public bodies or the writings of public officials and agencies be adopted with findings demonstrating the interest protected by the limitation and the need for protecting that interest. This bill would make legislative findings to that effect.
(1) Existing law, the California Consumer Privacy Act of 2018 (CCPA) , grants a consumer various rights with respect to personal information, as defined, that is collected or sold by a business, as defined, including the right to direct a business that collects sensitive personal information about the consumer to limit its use, as prescribed. Existing law defines "sensitive personal information" to mean, among other things, personal information that reveals a consumer's precise geolocation. Existing law, the California Privacy Rights Act of 2020, approved by the voters as Proposition 24 at the November 3, 2020, statewide general election, amended, added to, and reenacted the CCPA. This bill would prohibit a covered entity from collecting or processing the location information of an individual unless doing so is necessary to provide goods or services requested by that individual. The bill would impose various other restrictions on covered entities with regard to location information. The bill would define various terms for purposes of these provisions, including "location information" to mean information that pertains to or directly or indirectly reveals the present or past geographical location of an individual or device, as specified. This bill would require a covered entity to prominently display, at the point where location information is being captured, a notice to individuals stating that their location information is being collected, the name of the covered entity and service provider collecting the information, and a phone number and an internet website where the individual can obtain more information. The bill would require a covered entity to maintain and make available to the data subject a location privacy policy that includes specified information on data usage and management and is subject to a specified notice procedure. This bill would make a covered entity that violates these provisions liable for actual or statutory damages and other specified relief. The bill would authorize the Attorney General or other public prosecutors to bring an action to recover a civil penalty against a covered entity that violates these provisions. This bill would require a business, as defined by the CCPA, to comply with the above-described provisions. (2) Existing law, the Information Practices Act of 1977, prescribes a set of requirements, prohibitions, and remedies applicable to agencies, as defined, with regard to their collection, storage, and disclosure of personal information, as defined. This bill would prohibit a state or local agency, including an agency as defined under the Information Practices Act, from monetizing, as defined, location information. By imposing new requirements on local agencies, this bill would impose a state-mandated local program. (3) The California Constitution requires the state to reimburse local agencies and school districts for certain costs mandated by the state. Statutory provisions establish procedures for making that reimbursement. This bill would provide that, if the Commission on State Mandates determines that the bill contains costs mandated by the state, reimbursement for those costs shall be made pursuant to the statutory provisions noted above. (4) The California Consumer Privacy Act of 2020 authorizes the Legislature to amend the act to further the purposes and intent of the act by a majority vote of both houses of the Legislature, as specified. This bill would declare that its provisions further the purposes and intent of the California Privacy Rights Act of 2020.
Existing law requires that a local agency that maintains an internet website for use by the public to ensure that the internet website uses a ".gov" top-level domain or a ".ca.gov" second-level domain no later than January 1, 2029. Existing law requires that a local agency that maintains public email addresses to ensure that each email address provided to its employees uses a ".gov" domain name or a ".ca.gov" domain name no later than January 1, 2029. Existing law defines "local agency" for these purposes as a city, county, or city and county. This bill would recast these provisions by instead requiring a city, county, or city and county to comply with the above-described domain requirements and by deleting the term "local agency" from the above-described provisions. The bill would also require a special district, joint powers authority, or other political subdivision to comply with similar domain requirements no later than January 1, 2031. The bill would allow a community college district or community college to use a ".edu" domain to satisfy these requirements, and would specify that these requirements do not apply to a K–12 public school district. By adding to the duties of local officials, the bill would impose a state-mandated local program. The California Constitution requires the state to reimburse local agencies and school districts for certain costs mandated by the state. Statutory provisions establish procedures for making that reimbursement. This bill would provide that, if the Commission on State Mandates determines that the bill contains costs mandated by the state, reimbursement for those costs shall be made pursuant to the statutory provisions noted above.
The California AI Transparency Act requires a person that creates, codes, or otherwise produces a generative artificial intelligence system that has over 1,000,000 monthly visitors or users and is publicly accessible within the geographic boundaries of the state to make available an AI detection tool at no cost to the user that, among other things, allows a user to assess whether image, video, or audio content, or content that is any combination thereof, was created or altered by the covered provider's generative artificial intelligence system. The California Consumer Privacy Act of 2018 prohibits certain businesses from selling or sharing the personal information of consumers if the business has actual knowledge that the consumer is less than 16 years of age, unless the consumer, if the consumer is at least 13 years of age and less than 16 years of age, or the consumer's parent or guardian, if the consumer is less than 13 years of age, has affirmatively authorized the sale or sharing of the consumer's personal information. This bill, the Leading Ethical AI Development (LEAD) for Kids Act, would, among other things related to the use of certain artificial intelligence systems by children, prohibit a person, partnership, corporation, business entity, or state or local government agency that makes a companion chatbot available to users from making a companion chatbot available to a child unless the companion chatbot is not foreseeably capable of doing certain things that could harm a child, including encouraging the child to engage in self-harm, suicidal ideation, violence, consumption of drugs or alcohol, or disordered eating. The act would authorize the Attorney General to recover a certain civil penalty for a violation of the bill, as prescribed. The act would authorize a child who suffers actual harm as a result of a violation of the bill, or a parent or guardian acting on behalf of that child, to bring a civil action to recover, among other relief, actual damages. This bill would provide that its provisions are severable.
Existing law generally provides protections for minors on the internet, including the California Age-Appropriate Design Code Act that, among other things, requires a business that provides an online service, product, or feature likely to be accessed by children to do certain things, including estimate the age of child users with a reasonable level of certainty appropriate to the risks that arise from the data management practices of the business or apply the privacy and data protections afforded to children to all consumers and prohibits an online service, product, or feature from, among other things, using dark patterns to lead or encourage children to provide personal information beyond what is reasonably expected to provide that online service, product, or feature or to forego privacy protections. This bill, beginning January 1, 2027, would require, among other things related to age verification with respect to software applications, an operating system provider, as defined, to provide an accessible interface at account setup that requires an account holder, as defined, to indicate the birth date, age, or both, of the user of that device for the purpose of providing a signal regarding the user's age bracket to applications available in a covered application store and to provide a developer, as defined, who has requested a signal with respect to a particular user with a digital signal via a reasonably consistent real-time application programming interface regarding whether a user is in any of several age brackets, as prescribed. The bill would require a developer to request a signal with respect to a particular user from an operating system provider or a covered application store when the application is downloaded and launched. This bill would prohibit an operating system provider or a covered application store from using data collected from a third party in an anticompetitive manner, as specified. This bill would punish noncompliance with a civil penalty to be enforced by the Attorney General, as prescribed. This bill would declare its provisions to be severable.
Existing law authorizes a court to issue a restraining order to a person to prevent abuse, as specified, based on reasonable proof of a past act or acts of abuse. Existing law authorizes the order to be issued solely on the affidavit or testimony of the person requesting the restraining order. Existing law requires a manufacturer of a connected device to equip the device with a reasonable security feature or features that are appropriate to the nature and function of the device, appropriate to the information it may collect, contain, or transmit, and designed to protect the device and information contained in the device from unauthorized access, destruction, use, modification, or disclosure. This bill would authorize a survivor, as defined, or a designated representative of a survivor, to submit a device protection request to an account manager, as defined, seeking to terminate a perpetrator's access to a connected device or associated user account. The bill would define "survivor" for these purposes to mean an individual who has had specified criminal acts committed or allegedly committed against them or who cares for another individual against whom those criminal acts have been committed or allegedly committed, as provided. The bill would require an account manager, within 2 business days of receiving a complete device protection request, to terminate or disable the perpetrator's access to the connected device or user account, or to inform the survivor, in a clear and conspicuous manner, of any methods to reset the device to factory settings or a similar state that removes all account holders, as provided. The bill would specify the requirements for a device protection request and would impose certain requirements on an account manager in processing a request. By providing that a device protection request may include a copy of a signed affidavit, the bill would expand the crime of perjury, and thus impose a state-mandated local program. This bill would require the account manager to clearly describe the process to submit a device protection request on their internet website or mobile application and would prohibit the account manager from providing specified information to the perpetrator. The bill would require an account manager and any officer, director, employee, vendor, or agent thereof to treat any information submitted by a survivor or a designated representative of a survivor as confidential and securely dispose of the information, as provided. This bill would authorize enforcement of these provisions by injunction or civil penalty in any court action by any person injured by a violation of those provisions, the Attorney General, a district attorney, county counsel, a city attorney, or a city prosecutor, against an account manager or perpetrator, as provided. The bill would prohibit a waiver of these prohibitions and would declare that these provisions are severable. Existing law authorizes a court to issue an ex parte order for, among other things, disturbing the peace of the other party. Existing law provides that disturbing the peace of the other party may be committed directly or indirectly, including through the use of a third party, and by any method or through any means including, but not limited to, telephone, online accounts, text messages, internet-connected devices, or other electronic technologies. This bill would provide that, for purposes of those provisions, an internet-connected device includes a connected device as described in the bill. The California Constitution requires the state to reimburse local agencies and school districts for certain costs mandated by the state. Statutory provisions establish procedures for making that reimbursement. This bill would provide that no reimbursement is required by this act for a specified reason.